WanaKiwi, allows machines infected by the WannaCry ransomware to recover decryption keys. If you are LUCKY enough and the decryption keys are still in computer memory, this tool will recover the private user key in memory and dump it as 00000000.dky using which it will decrypt all encypted files without the need to pay ransom.

Do Note:

Given the fact this method relies on scanning the address space of the process that generated those keys, this means that if this process had been killed by, for instance, a reboot - the original process memory will be lost. It is very important for users to NOT reboot their system before trying this tool.

Secondly, because of the same reason we do not know how long the prime numbers will be kept in the address space before being reused by the process. This is why it is important to try this utility ASAP.

This is not a perfect tool, but this has been so far the best solution for victims who had no backup.

Site Search:

Search form

This is just one of the many helpful tips we have posted, You can find more stories here, Do subscribe to updates using your favorite RSS feed reader or using the secure FeedBurner email update form on top of this post.